Introduction |
|
xx | |
Part I: Installing and Configuring Active Directory Domain Services |
|
|
Chapter 1 Introducing Active Directory 2016 |
|
|
3 | (18) |
|
"Do I Know This Already?" Quiz |
|
|
3 | (4) |
|
|
7 | (1) |
|
Identity and Active Directory 2016 |
|
|
7 | (2) |
|
Active Directory Domain Services (AD DS) |
|
|
9 | (4) |
|
|
9 | (1) |
|
Containers and Organizational Units |
|
|
10 | (1) |
|
|
11 | (1) |
|
|
11 | (1) |
|
Group Policy Objects (GPOs) |
|
|
12 | (1) |
|
Active Directory Federation Services (AD FS) |
|
|
13 | (1) |
|
|
13 | (1) |
|
Claims-Based Authentication |
|
|
14 | (1) |
|
|
14 | (1) |
|
Active Directory Certificate Services (AD CS) |
|
|
14 | (1) |
|
Active Directory Rights Management Services (AD RMS) |
|
|
15 | (1) |
|
|
15 | (1) |
|
|
16 | (1) |
|
|
16 | (1) |
|
|
16 | (1) |
|
Complete Tables and Lists from Memory |
|
|
17 | (1) |
|
|
17 | (1) |
|
End-of-Chapter Review Questions |
|
|
18 | (3) |
|
Chapter 2 Installing and Configuring Domain Controllers |
|
|
21 | (42) |
|
"Do I Know This Already?" Quiz |
|
|
21 | (5) |
|
|
26 | (1) |
|
|
26 | (7) |
|
|
26 | (1) |
|
Installing AD DS from Server Manager |
|
|
27 | (3) |
|
Promoting the Server to Domain Controller |
|
|
30 | (3) |
|
Adding or Removing a Domain Controller from a Domain |
|
|
33 | (6) |
|
Multimaster Replication and FSMO Roles |
|
|
33 | (2) |
|
Forest and Domain Functional Levels |
|
|
35 | (1) |
|
Adding a New Domain Controller to an Existing Domain |
|
|
35 | (3) |
|
Demoting a Server from Domain Controller |
|
|
38 | (1) |
|
Upgrading a Domain Controller |
|
|
39 | (2) |
|
Installing AD DS on a Server Core Installation |
|
|
41 | (3) |
|
Installing AD DS with PowerShell |
|
|
41 | (1) |
|
Promoting a Server to Domain Controller with PowerShell |
|
|
42 | (2) |
|
Installing a Domain Controller with Install from Media (IFM) |
|
|
44 | (3) |
|
Creating the Media for Installation |
|
|
44 | (2) |
|
Deploying a Domain Controller Using IFM |
|
|
46 | (1) |
|
Installing and Configuring a Read-Only Domain Controller (RODC) |
|
|
47 | (3) |
|
Configuring Domain Controller Cloning |
|
|
50 | (4) |
|
Requirements to Clone a Virtual Domain Controller |
|
|
51 | (1) |
|
Creating DCCIoneConfig.xml |
|
|
51 | (3) |
|
Exporting and Importing the Cloned DC |
|
|
54 | (1) |
|
Resolving DNS SRV Record Registration Issues |
|
|
54 | (1) |
|
Configuring a Global Catalog Server |
|
|
55 | (1) |
|
Transferring and Seizing Operations Master Roles |
|
|
55 | (3) |
|
|
58 | (1) |
|
|
58 | (1) |
|
Complete Tables and Lists from Memory |
|
|
59 | (1) |
|
|
59 | (1) |
|
End-of-Chapter Review Questions |
|
|
59 | (4) |
|
Chapter 3 Creating and Managing Active Directory Users and Computers |
|
|
63 | (36) |
|
"Do I Know This Already?" Quiz |
|
|
63 | (4) |
|
|
67 | (1) |
|
Creating, Copying, Configuring, and Deleting Users and Computers |
|
|
67 | (10) |
|
Creating and Configuring a New User |
|
|
67 | (4) |
|
Creating and Configuring a New Computer |
|
|
71 | (2) |
|
|
73 | (2) |
|
|
75 | (1) |
|
|
76 | (1) |
|
Automating the Creation of Active Directory Accounts |
|
|
77 | (6) |
|
|
78 | (4) |
|
|
82 | (1) |
|
Performing Bulk Active Directory Operations |
|
|
83 | (4) |
|
Comma Separated Value Data Exchange (csvde) |
|
|
84 | (2) |
|
LDAP Data Interchange Format Data Exchange (ldifde) |
|
|
86 | (1) |
|
|
87 | (3) |
|
Implementing Offline Domain Join |
|
|
90 | (2) |
|
Managing Inactive and Disabled Accounts |
|
|
92 | (2) |
|
Automating Unlocking of Disabled Accounts Using Windows PowerShell |
|
|
93 | (1) |
|
Automating Password Resets Using Windows PowerShell |
|
|
94 | (1) |
|
|
94 | (1) |
|
|
95 | (1) |
|
Complete Tables and Lists from Memory |
|
|
95 | (1) |
|
|
96 | (1) |
|
End-of-Chapter Review Questions |
|
|
96 | (3) |
|
Chapter 4 Creating and Managing Active Directory Groups and Organizational Units |
|
|
99 | (32) |
|
"Do I Know This Already?" Quiz |
|
|
99 | (4) |
|
|
103 | (1) |
|
Creating, Copying, Configuring, and Deleting Groups and OUs |
|
|
103 | (12) |
|
Active Directory Groups and Active Directory OUs |
|
|
103 | (4) |
|
|
103 | (2) |
|
|
105 | (1) |
|
|
105 | (1) |
|
|
106 | (1) |
|
Working with Active Directory Groups |
|
|
107 | (2) |
|
Working with Active Directory OUs |
|
|
109 | (2) |
|
Automate Groups and OUs with PowerShell |
|
|
111 | (3) |
|
Converting Group Scope and Type |
|
|
114 | (1) |
|
Configuring Group Nesting |
|
|
115 | (3) |
|
|
115 | (2) |
|
Enumerating Group Membership |
|
|
117 | (1) |
|
Delegating the Creation and Management of Groups and OUs |
|
|
118 | (4) |
|
Managing Group Membership Using Group Policy |
|
|
122 | (2) |
|
Managing Default Active Directory Containers |
|
|
124 | (1) |
|
|
125 | (1) |
|
|
125 | (1) |
|
Complete Tables and Lists from Memory |
|
|
126 | (1) |
|
|
126 | (1) |
|
End-of-Chapter Review Questions |
|
|
126 | (5) |
Part II: Managing and Maintaining Active Directory Domain Services |
|
|
Chapter 5 Configuring Service Authentication and Account Policies |
|
|
131 | (34) |
|
"Do I Know This Already?" Quiz |
|
|
131 | (4) |
|
|
135 | (1) |
|
Creating and Configuring Service Accounts |
|
|
135 | (9) |
|
|
136 | (3) |
|
|
139 | (3) |
|
Group Managed Service Accounts (gMSAs) |
|
|
142 | (1) |
|
|
143 | (1) |
|
Configuring Kerberos Constrained Delegation (KCD) |
|
|
144 | (5) |
|
|
145 | (2) |
|
Managing Service Principal Names (SPNs) |
|
|
147 | (2) |
|
Configuring Default Domain Account Policies |
|
|
149 | (6) |
|
Configuring Domain and Local User Password Policy Settings |
|
|
150 | (1) |
|
Configuring Account Lockout Policy Settings |
|
|
151 | (2) |
|
Configuring Kerberos Policy Settings Within Group Policy |
|
|
153 | (2) |
|
Configuring and Applying Password Settings Objects (PSOs) |
|
|
155 | (4) |
|
|
155 | (1) |
|
|
156 | (2) |
|
Delegating Password Settings Management |
|
|
158 | (1) |
|
|
159 | (1) |
|
|
160 | (1) |
|
Complete Tables and Lists from Memory |
|
|
160 | (1) |
|
|
161 | (1) |
|
End-of-Chapter Review Questions |
|
|
161 | (4) |
|
Chapter 6 Maintaining Active Directory |
|
|
165 | (34) |
|
"Do I Know This Already?" Quiz |
|
|
165 | (4) |
|
|
169 | (1) |
|
Configuring Active Directory Snapshots |
|
|
169 | (4) |
|
|
169 | (1) |
|
Creating and Mounting a Snapshot |
|
|
169 | (2) |
|
|
171 | (2) |
|
Backing Up and Restoring Active Directory and SYSVOL |
|
|
173 | (8) |
|
Backing Up Active Directory |
|
|
173 | (1) |
|
Restoring Active Directory |
|
|
174 | (1) |
|
|
175 | (3) |
|
|
178 | (1) |
|
Configuring and Restoring Objects by Using the Active Directory Recycle Bin |
|
|
179 | (2) |
|
Managing Active Directory Offline |
|
|
181 | (3) |
|
Performing Offline Defragmentation of an Active Directory Database |
|
|
182 | (2) |
|
|
184 | (1) |
|
Configuring Replication to Read-Only Domain Controllers (RODCs) |
|
|
185 | (4) |
|
Configuring Password Replication Policy (PRP) for RODC |
|
|
186 | (3) |
|
Monitoring and Managing Replication |
|
|
189 | (4) |
|
Upgrading SYSVOL Replication to Distributed File System Replication (DFSR) |
|
|
192 | (1) |
|
|
193 | (1) |
|
|
194 | (1) |
|
Complete Tables and Lists from Memory |
|
|
194 | (1) |
|
|
195 | (1) |
|
End-of-Chapter Review Questions |
|
|
195 | (4) |
|
Chapter 7 Configuring Active Directory in a Complex Enterprise Environment |
|
|
199 | (26) |
|
"Do I Know This Already?" Quiz |
|
|
199 | (3) |
|
|
202 | (1) |
|
Deploying Windows Server 2016 Domain Controllers Within a Pre-Existing Active Directory Environment |
|
|
202 | (4) |
|
Upgrading Existing Domains and Forests |
|
|
202 | (1) |
|
Configuring Domain and Forest Functional Levels |
|
|
203 | (2) |
|
Configuring Multiple User Principal Name (UPN) Suffixes |
|
|
205 | (1) |
|
|
206 | (7) |
|
Configuring Forest, External, Realm, and Shortcut Trusts |
|
|
207 | (4) |
|
Configuring SID Filtering |
|
|
211 | (1) |
|
Configuring Name Suffix Routing |
|
|
212 | (1) |
|
|
213 | (8) |
|
Configuring Sites and Subnets |
|
|
214 | (3) |
|
|
214 | (2) |
|
|
216 | (1) |
|
Creating and Configuring Site Links |
|
|
217 | (2) |
|
Managing Sites with PowerShell |
|
|
219 | (2) |
|
|
221 | (1) |
|
|
221 | (1) |
|
Complete Tables and Lists from Memory |
|
|
222 | (1) |
|
|
222 | (1) |
|
End-of-Chapter Review Questions |
|
|
222 | (3) |
Part III: Creating and Managing Group Policy |
|
|
Chapter 8 Creating and Managing Group Policy Objects (GPOs) |
|
|
225 | (30) |
|
"Do I Know This Already?" Quiz |
|
|
225 | (3) |
|
|
228 | (1) |
|
Introduction to Group Policy |
|
|
228 | (4) |
|
Creating Group Policy Objects |
|
|
229 | (1) |
|
|
230 | (2) |
|
|
232 | (2) |
|
Backing Up, Importing, Copying, and Restoring GPOs |
|
|
234 | (9) |
|
Using the Group Policy Management Editor (GPME) |
|
|
234 | (3) |
|
Using PowerShell to Manage GPOs |
|
|
237 | (3) |
|
Creating and Configuring a Migration Table |
|
|
240 | (2) |
|
|
242 | (1) |
|
Delegating Group Policy Management |
|
|
243 | (2) |
|
Detecting Health Issues Using the Group Policy Infrastructure Status Dashboard |
|
|
245 | (3) |
|
Group Policy Infrastructure |
|
|
245 | (1) |
|
Group Policy Infrastructure Status Dashboard |
|
|
246 | (2) |
|
|
248 | (3) |
|
Configuring Multiple Local Group Policies |
|
|
248 | (2) |
|
Configuring a Central Store |
|
|
250 | (1) |
|
|
251 | (1) |
|
|
251 | (1) |
|
Complete Tables and Lists from Memory |
|
|
252 | (1) |
|
|
252 | (1) |
|
End-of-Chapter Review Questions |
|
|
252 | (3) |
|
Chapter 9 Configuring Group Policy Processing |
|
|
255 | (20) |
|
"Do I Know This Already?" Quiz |
|
|
255 | (3) |
|
|
258 | (1) |
|
Configuring Processing Order, Precedence, and Blocking of Inheritance |
|
|
258 | (3) |
|
Processing Order and Precedence |
|
|
258 | (2) |
|
|
260 | (1) |
|
Configuring Security Filtering and Windows Management Instrumentation (WMI) Filtering |
|
|
261 | (5) |
|
|
261 | (2) |
|
|
263 | (2) |
|
|
265 | (1) |
|
|
266 | (5) |
|
Configure and Manage Slow Link Processing and Group Policy Caching |
|
|
267 | (1) |
|
Configure Client-Side Extension (CSE) Behavior |
|
|
268 | (1) |
|
Force a Group Policy Update |
|
|
269 | (2) |
|
|
271 | (1) |
|
|
271 | (1) |
|
Complete Tables and Lists from Memory |
|
|
272 | (1) |
|
|
272 | (1) |
|
End-of-Chapter Review Questions |
|
|
272 | (3) |
|
Chapter 10 Configuring Group Policy Settings |
|
|
275 | (18) |
|
"Do I Know This Already?" Quiz |
|
|
275 | (2) |
|
|
277 | (1) |
|
Configuring Software Installation |
|
|
277 | (2) |
|
Configuring Folder Redirection |
|
|
279 | (2) |
|
|
281 | (3) |
|
Configuring Administrative Templates |
|
|
284 | (4) |
|
Importing a Custom Administrative Template File |
|
|
285 | (1) |
|
Configuring Property Filters for Administrative Templates |
|
|
286 | (2) |
|
|
288 | (1) |
|
|
288 | (1) |
|
Complete Tables and Lists from Memory |
|
|
289 | (1) |
|
|
289 | (1) |
|
End-of-Chapter Review Questions |
|
|
290 | (3) |
|
Chapter 11 Configuring Group Policy Preferences |
|
|
293 | (24) |
|
"Do I Know This Already?" Quiz |
|
|
293 | (2) |
|
Configuring Control Panel Settings |
|
|
295 | (8) |
|
Configuring Printer Preferences |
|
|
296 | (2) |
|
Configuring Power Options |
|
|
298 | (1) |
|
Configuring Internet Explorer Settings |
|
|
299 | (2) |
|
Configuring Item-Level Targeting |
|
|
301 | (2) |
|
Configuring Windows Settings |
|
|
303 | (9) |
|
Configuring Custom Registry Settings |
|
|
304 | (2) |
|
Defining Network Drive Mappings |
|
|
306 | (2) |
|
Configuring File and Folder Deployment |
|
|
308 | (2) |
|
Configuring Shortcut Deployment |
|
|
310 | (2) |
|
|
312 | (1) |
|
|
312 | (1) |
|
Complete Tables and Lists from Memory |
|
|
313 | (1) |
|
|
313 | (1) |
|
End-of-Chapter Review Questions |
|
|
313 | (4) |
Part IV: Implementing Active Directory Certification Services |
|
|
Chapter 12 Installing and Configuring Active Directory Certificate Services |
|
|
317 | (26) |
|
"Do I Know This Already?" Quiz |
|
|
317 | (3) |
|
|
320 | (1) |
|
Installing Active Directory Integrated Enterprise Certificate Authority |
|
|
320 | (8) |
|
Installing AD CS on a Server |
|
|
320 | (2) |
|
Configuring AD CS on a Server |
|
|
322 | (6) |
|
Installing Offline Root and Subordinate CAs |
|
|
328 | (1) |
|
Configuring Certificate Revocation List Distribution Points |
|
|
328 | (8) |
|
Creating New CRL Distribution Points (CDPs) |
|
|
329 | (2) |
|
Installing and Configuring Online Responders |
|
|
331 | (5) |
|
Configuring CA Backup, Recovery, and Administrative Role Separation |
|
|
336 | (3) |
|
Configuring CA Backup and Recovery |
|
|
336 | (1) |
|
Administrative Role Separation |
|
|
337 | (2) |
|
|
339 | (1) |
|
|
339 | (1) |
|
Complete Tables and Lists from Memory |
|
|
340 | (1) |
|
|
340 | (1) |
|
End-of-Chapter Review Questions |
|
|
340 | (3) |
|
Chapter 13 Managing Certificates |
|
|
343 | (24) |
|
"Do I Know This Already?" Quiz |
|
|
343 | (3) |
|
|
346 | (1) |
|
Managing Certificate Templates |
|
|
346 | (3) |
|
Enabling Certificate Templates |
|
|
346 | (2) |
|
|
348 | (1) |
|
Managing Certificate Deployment, Validation, Revocation, and Renewal |
|
|
349 | (6) |
|
|
350 | (1) |
|
|
351 | (3) |
|
|
354 | (1) |
|
Managing Certificate Autoenrollment Using Group Policies |
|
|
355 | (3) |
|
Configuring Key Archival and Recovery |
|
|
358 | (5) |
|
|
363 | (1) |
|
|
363 | (1) |
|
Complete Tables and Lists from Memory |
|
|
364 | (1) |
|
|
364 | (1) |
|
End-of-Chapter Review Questions |
|
|
364 | (3) |
Part V: Implementing Identity Federation and Access Solutions |
|
|
Chapter 14 Installing and Configuring Active Directory Federation Services |
|
|
367 | (26) |
|
"Do I Know This Already?" Quiz |
|
|
367 | (3) |
|
|
370 | (1) |
|
Implementing Claims-Based Authentication |
|
|
370 | (8) |
|
Installing a Standalone AD FS Server |
|
|
370 | (6) |
|
Installing an AD FS Server Farm |
|
|
376 | (2) |
|
Configuring Authentication |
|
|
378 | (3) |
|
Configuring Authentication Policies |
|
|
378 | (2) |
|
Configuring Multi-Factor Authentication |
|
|
380 | (1) |
|
Implementing and Configuring Device Registration |
|
|
381 | (3) |
|
Integrating AD FS with Microsoft Passport |
|
|
384 | (1) |
|
Configuring AD FS to Enable Authentication of Users Stored in LDAP Directories |
|
|
385 | (3) |
|
|
388 | (1) |
|
|
388 | (1) |
|
Complete Tables and Lists from Memory |
|
|
389 | (1) |
|
|
389 | (1) |
|
End-of-Chapter Review Questions |
|
|
390 | (3) |
|
Chapter 15 Implementing Web Application Proxy |
|
|
393 | (16) |
|
"Do I Know This Already?" Quiz |
|
|
393 | (2) |
|
|
395 | (1) |
|
Installing and Configuring Web Application Proxy |
|
|
395 | (4) |
|
Installing Web Application Proxy |
|
|
395 | (2) |
|
Implementing WAP in Pass-Through Mode |
|
|
397 | (2) |
|
Implementing WAP as AD FS Proxy |
|
|
399 | (6) |
|
|
405 | (1) |
|
|
405 | (1) |
|
Complete Tables and Lists from Memory |
|
|
405 | (1) |
|
|
405 | (1) |
|
End-of-Chapter Review Questions |
|
|
406 | (3) |
|
Chapter 16 Installing and Configuring Active Directory Rights Management Services |
|
|
409 | (22) |
|
"Do I Know This Already?" Quiz |
|
|
409 | (3) |
|
|
412 | (1) |
|
Installing an Active Directory Rights Management Services Server |
|
|
412 | (6) |
|
|
412 | (2) |
|
|
414 | (2) |
|
Managing AD RMS Service Connection Point |
|
|
416 | (2) |
|
Managing AD RMS Templates and Exclusion Policies |
|
|
418 | (5) |
|
|
418 | (4) |
|
Configuring Exclusion Policies |
|
|
422 | (1) |
|
Backing Up and Restoring AD RMS |
|
|
423 | (4) |
|
|
427 | (1) |
|
|
427 | (1) |
|
Complete Tables and Lists from Memory |
|
|
427 | (1) |
|
|
428 | (1) |
|
End-of-Chapter Review Questions |
|
|
428 | (3) |
|
Chapter 17 Final Preparation |
|
|
431 | (8) |
|
Tools for Final Preparation |
|
|
431 | (5) |
|
Pearson Cert Practice Test Engine and Questions on the Website |
|
|
431 | (2) |
|
Accessing the Pearson Test Prep Software Online |
|
|
432 | (1) |
|
Accessing the Pearson Test Prep Software Offline |
|
|
432 | (1) |
|
|
433 | (1) |
|
|
434 | (1) |
|
|
435 | (1) |
|
|
435 | (1) |
|
Chapter-Ending Review Tools |
|
|
435 | (1) |
|
Suggested Plan for Final Review/Study |
|
|
436 | (1) |
|
|
436 | |
Part VI: Appendices |
|
|
Appendix A: Answers to the "Do I Know This Already?" Quizzes and End-of-Chapter Review Questions |
|
|
439 | (22) |
Glossary of Key Terms |
|
461 | (12) |
Index |
|
473 | |